Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: PHP 4.0 Bug #2360: Chmod in safe mode allows setuid bits
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-11214@lists.php.net to get a copy of this message
> The chmod function can set the setuid bit on a file that the script has created. Since these > files are owned by the Web server uid, even in safe mode you can create a setuid copy of /bin/sh > using a PHP script and then use the setuid shell to access files as the Web server user. I can > supply my test script upon request. > > This issue is a moot point when safe mode is not in effect, since then you can simply exec any > shell command you want as the Web server uid. Sites that do use safe mode to restrict program > execution under the Web server uid are more prone to the problem, and then only if they offer > interactive login access and also have user-writable file systems that allow setuid program > execution. This is a fairly small set of sites but it's probably nonempty. > > Chmod should probably not allow setuid bits when safe mode is in effect. Hrm, but in safe-mode you can only exec() stuff from the safe-mode-exec-dir so I am not quite sure how you would launch this setuid program that you might have managed to create. Through cgi perhaps? I agree that we probably should have a look at safe-mode and chmod(), but I don't see a clear exploit here. -Rasmus

« previous php.dev (#11214) next »